Re: segmentation fault in rlm_attr_rewrite and eaptls module

2007-04-09 Thread nikitha
I am trying to download the branch_1_1 from CVS but i am getting error as: Unknown host Ping to 64.24.0.50 (cvs.freeradius.org) not reachable. Is the cvs.freeradius.org server is down? Thanks, Sumithra On 4/7/07, Alan DeKok [EMAIL PROTECTED] wrote: nikitha wrote: Thanks for your

Re: segmentation fault in rlm_attr_rewrite and eaptls module

2007-04-09 Thread Alan DeKok
nikitha wrote: I am trying to download the branch_1_1 from CVS but i am getting error as: Unknown host Ping to 64.24.0.50 http://64.24.0.50 (cvs.freeradius.org http://cvs.freeradius.org) not reachable. Is the cvs.freeradius.org http://cvs.freeradius.org server is down? I can see it as

Re: segmentation fault in rlm_attr_rewrite and eaptls module

2007-04-09 Thread nikitha
I could ping to freeradius.org but not to cvs.freeradius.org. Anyhow i will try it once again after some time. Thanks. On 4/9/07, Alan DeKok [EMAIL PROTECTED] wrote: nikitha wrote: I am trying to download the branch_1_1 from CVS but i am getting error as: Unknown host Ping to 64.24.0.50

two database

2007-04-09 Thread Nirmal
Hi i m using freeradius 0.9 is it possible to select two sql databases in sql.conf ? how ? Thanks In Advance Regards Nirmal Patel 9323704733 - TV dinner still cooling? Check out Tonight's Picks on Yahoo! TV.- List

Re: two database

2007-04-09 Thread Alan DeKok
Nirmal wrote: Hi i m using freeradius 0.9 Why? is it possible to select two sql databases in sql.conf ? Yes. how ? See the documentation in the recent versions. Alan DeKok. -- http://deployingradius.com - The web site of the book http://deployingradius.com/blog/ - The

Re: Alternate proxying methods.

2007-04-09 Thread Arran Cudbard-Bell
Alan DeKok wrote: Arran Cudbard-Bell wrote: The obvious solution is to actually direct users at a realm, instead of relying on DEFAULT entries... But as soon as a user hits the rlm_realm they will be proxied... Only if you define authhost and accthost. If those don't exist (or

Re: two database

2007-04-09 Thread Nirmal
can i use two sql database in sql.conf for free radius version 0.9 ? currently i m using freeradius 0.9 + MySQL 3.23 + PPPoE on linux (NAS) authentication and accounting is happening in one database. i have a very large user database and i want to assign roaming profile to my

Re: two database

2007-04-09 Thread Nirmal
can i use two sql database in sql.conf for free radius version 0.9 ? currently i m using freeradius 0.9 + MySQL 3.23 + PPPoE on linux (NAS) authentication and accounting is happening in one database. i have a very large user database and i want to assign roaming profile to my

Re: two database

2007-04-09 Thread Arran Cudbard-Bell
Nirmal wrote: can i use two sql database in sql.conf for free radius version 0.9 ? currently i m using freeradius 0.9 + MySQL 3.23 + PPPoE on linux (NAS) authentication and accounting is happening in one database. i have a very large user database and i want to assign roaming profile

freeradius and cisco hidden share

2007-04-09 Thread John Baker
Hello *I'm running FreeRadius with the standard Ubuntu Breezy package that reads as freeradius 1.0.4-2. Its been the connection to the LDAP backend for authentication on an old Cisco 3640 with IOS 12.2(23) for quite a while. I'm trying to setup a new 2811 router with IOS 12.4(11)T1 and am

Re: freeradius and cisco hidden share

2007-04-09 Thread Alan DeKok
John Baker wrote: The setup works fine if I use a password like testing123 on both ends. But when I use radius-server key 7 to encrypt it breaks. As in... what happens? The current setup does use this so I know it works. But in all the documentation I've been weeding** through** on

Re: freeradius and cisco hidden share

2007-04-09 Thread John Baker
Hello I'm certain was using the right command. The number 7 in the line tells the router that a hidden key will follow. coltrane(config)#radius-server key ? 0 Specifies an UNENCRYPTED key will follow 7 Specifies HIDDEN key will follow LINE The UNENCRYPTED (cleartext) shared key

RE: freeradius and cisco hidden share

2007-04-09 Thread King, Michael
It sounds like your trying to encrypt the shared secret in the router config. Or, your trying to copy the encrypted shared secret and paste it. (The 7 is what tipped me off) First, you need to verify that you have the password-encryption is enabled in the IOS. This is the magic that makes

RE: freeradius and cisco hidden share

2007-04-09 Thread King, Michael
One further comment. The shared secret in FreeRADIUS CANNOT be the really long number in the IOS config file. This is an encrypted hash of the REAL secret. - List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Re: freeradius and cisco hidden share

2007-04-09 Thread Peter Nixon
Hi Michael Please add any info you feel is relevant to: http://wiki.freeradius.org/Cisco Cheers Peter On Mon 09 Apr 2007, King, Michael wrote: It sounds like your trying to encrypt the shared secret in the router config. Or, your trying to copy the encrypted shared secret and paste it.

RE: [m0n0wall] Captive Portal and Radius

2007-04-09 Thread Alex M
Are we talking about M0n0 as a NAS here? If yes, why not to mod the boxy to do internal counting of the section and then talk to the radius with final data? -Original Message- From: YvesDM [mailto:[EMAIL PROTECTED] Sent: Monday, April 09, 2007 11:37 AM To: Peter Boosten Cc:

Re: freeradius and cisco hidden share

2007-04-09 Thread John Baker
Okay, this is the piece I was trying to figure out. :) Like I said in a follow up I found that copying the key out of the old cisco config and the old one in the users.conf worked. Initially I made an error on this cisco end when copying that made it fail. So the piece of confusion is how you

Re: Problem with freeradius and mysql

2007-04-09 Thread José Christian Rodríguez
Thank all for your help. My freeradius with mysql is working now. Christian - Original Message - From: satish patel To: FreeRadius users mailing list Sent: Friday, April 06, 2007 2:55 AM Subject: Re: Problem with freeradius and mysql Dear all Here I

RE: freeradius and cisco hidden share

2007-04-09 Thread King, Michael
-Original Message- So the piece of confusion is how you get that encrypted hash in there in the first place when configuring a new key. Service password-encryption http://www.cisco.com/en/US/products/sw/iosswrel/ps5207/products_command_

Reject user without realm

2007-04-09 Thread Marcos Roberto Greiner
Hi, I'm trying to use FreeRadius with Realms (using the form [EMAIL PROTECTED]). Basically, if a user uses [EMAIL PROTECTED], I want Radius to authenticate locally. If it's @provider2.com, 3.com, etc, on other servers listed in proxy.conf. The problem I'm having is that if a user adds no realm,

Re: Freeradius+OpenLDAP+SAMBA+Windows Domain Logon.

2007-04-09 Thread Sérgio Kojima
Sorry for my delay :P The Samba version is '3.0.23c-2' and works fine like my old AD Domain. The winbind package is not install, but there is a process running 'winbindd', it was installed when i install the samba. I use a Debian linux server. Robinson Santos, where u from ? :) - List

Re: Reject user without realm

2007-04-09 Thread Arran Cudbard-Bell
Marcos Roberto Greiner wrote: Hi, I'm trying to use FreeRadius with Realms (using the form [EMAIL PROTECTED]). Basically, if a user uses [EMAIL PROTECTED], I want Radius to authenticate locally. If it's @provider2.com, 3.com, etc, on other servers listed in proxy.conf. The problem I'm

Re: Reject user without realm

2007-04-09 Thread Kevin Bonner
On Monday 09 April 2007 14:32:31 Marcos Roberto Greiner wrote: The problem I'm having is that if a user adds no realm, only the user, the server is autenticating locally. I wanted it to deny the authentication. How should I proceed? A username with no realm will match the NULL realm. You can

Re: Reject user without realm

2007-04-09 Thread Roberto Greiner
Arran Cudbard-Bell wrote: Marcos Roberto Greiner wrote: Hi, I'm trying to use FreeRadius with Realms (using the form [EMAIL PROTECTED]). Basically, if a user uses [EMAIL PROTECTED], I want Radius to authenticate locally. If it's @provider2.com, 3.com, etc, on other servers listed in

Mac OS 10.4 Radius

2007-04-09 Thread John Warf
I am looking to see if anyone has a install of FreeRadius running on a Mac OS 10.4 server binding to an LDAP server. We are looking at doing this and I was wanting to see if anyone has already got a binary out there or some words of advise for it. I currently have FreeRadius running on a

Re: Reject user without realm

2007-04-09 Thread Roberto Greiner
Kevin Bonner wrote: On Monday 09 April 2007 14:32:31 Marcos Roberto Greiner wrote: The problem I'm having is that if a user adds no realm, only the user, the server is autenticating locally. I wanted it to deny the authentication. How should I proceed? A username with no realm will

Accounting question

2007-04-09 Thread Ian Truelsen
When I connect to my AP, authenticated by freeradius using EAP-TLS, I get an entry into radpostauth, entries in /var/log/radius/radacct/192.168.3.115/detail-auth and detail-reply files, but I am not getting any entries into radacct. I don't know whether this is because the NAS is not sending any

Re: Accounting question

2007-04-09 Thread Alan DeKok
Ian Truelsen wrote: When I connect to my AP, authenticated by freeradius using EAP-TLS, I get an entry into radpostauth, entries in /var/log/radius/radacct/192.168.3.115/detail-auth and detail-reply files, but I am not getting any entries into radacct. I don't know whether this is because the

RadiusExpert Wiki

2007-04-09 Thread Mike McCauley
Hi all, Open System Consultants (OSC) has established a free resource for the RADIUS user community to collect and share information about configuring and implementing RADIUS protocol devices and software. RadiusExpert:Community Portal at http://www.open.com.au/wiki/index.php/Main_Page will

Re: Alternate proxying methods.

2007-04-09 Thread Alan DeKok
Arran Cudbard-Bell wrote: So... Replicate-To-Realm doesn't work. I'd be curious to know what it does for you. ... But that would be because it's defined as attribute 1049 in dictionary.freeradius.internal Yes. Well obviously someone wanted to implement it once, but never got round to

Problem with mschap, ntlm_auth and a conditional syntax

2007-04-09 Thread latin
Hello, I use ntlm_auth in mschapv2 (freeradius 20070409) by the following line in radiusd.conf: ntlm_auth = /usr/local/eduroam/progs/ntlm/ntlm_auth.pl --request-nt-key --username=%{Stripped-User-Name:-%{User-Name:-None}} --challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00

Re: Problem with mschap, ntlm_auth and a conditional syntax

2007-04-09 Thread Lukasz Lacinski
Below is my previous e-mail, but with output from freeradius in format easier to read. I use ntlm_auth in mschapv2 (freeradius 20070409) by the following line in radiusd.conf: ntlm_auth = /usr/local/eduroam/progs/ntlm/ntlm_auth.pl --request-nt-key --username=%{Stripped-User-Name:-%{User-Name

Re: Accounting question

2007-04-09 Thread Ethan Dicks
On 4/9/07, Alan DeKok [EMAIL PROTECTED] wrote: Ian Truelsen wrote: When I connect to my AP, authenticated by freeradius using EAP-TLS, I get an entry into radpostauth, entries in /var/log/radius/radacct/192.168.3.115/detail-auth and detail-reply files, but I am not getting any entries

Re: Can i do that?

2007-04-09 Thread Marat Rysbekov
Hello, apolyxrono. OK, an example. I use freeradius server to do the accounting for my DSL clients. There are two tables in the accounting scheme: 1. dsl_accounting. This is a shorter version of radacct, containing only the fields I found to be useful to me. MySQL create statement: CREATE